Skip to content
Perimeter
How it works What it can detect Limitations FAQ Support Coming soon

Clear data practices

Privacy Policy

This policy distinguishes data handled by the Perimeter app from ordinary operational data handled by this website.

Last updated September 9, 2026

Summary

Perimeter performs its core signal analysis on your iPhone and keeps its records local. The app contains no advertising SDK, no third-party analytics SDK, and no third-party crash-reporting SDK, and it does not send your observations to Perimeter-operated servers. Core use requires no Perimeter account, advertising identifier, analytics SDK, or Perimeter telemetry. Information leaves the device only where this policy says it does: when a feature uses an Apple platform service, or when you deliberately export, share, or submit something.

App sensing and permissions

Bluetooth is used to observe supported nearby advertisements. Perimeter does not pair with or connect to the Bluetooth devices it observes. During a Place Check, Local Network access is used, when available, to observe advertised service names and test supported camera-related services on the Wi-Fi network your iPhone is already using. These local checks do not upload the observed network data to Perimeter.

NFC access is used only when you start the physical-tracker workflow and hold a compatible tag near your iPhone. Camera and photo access is used only when you choose a lens, reference-photo, or physical-inspection tool. Notifications are used, with your permission, to surface supported review items and Journey updates. You can change each permission in iOS Settings.

Perimeter app data

Depending on the features you use, records stored on your device may include supported Bluetooth observations and locally pseudonymous candidate identifiers, Area Scan records, Place Check records (Guided Room Check and Car Sweep), sparse tracker waypoints, familiar-place profiles, Journey records, Wi-Fi or local-network service names, NFC payloads read from a physical tag you scanned, and photos or notes you choose to save.

Core use does not require an account. Perimeter does not upload scan results, nearby-device records, routes, photos, or saved checks to Perimeter-operated servers, and it does not need to identify nearby people to provide its core awareness features.

CoreBluetooth peripheral identifiers are transformed into local pseudonyms before they are stored. They are not exported and are not treated as a product or person identity.

App location data

If you allow Location Services, Perimeter uses approximate location to evaluate whether a tracker-like observation pattern appears to travel with you. Location is sampled sparsely for this purpose rather than used to create a continuous location history. A sample is retained only when it is close in time to an observation and accurate enough to be meaningful, the number of retained waypoints is bounded, and waypoints are removed after 30 days.

Maps shown on a finding, an Area Scan, a Place Check, or a Familiar Place render location context that was already stored locally for that record. Opening one of these views does not start continuous location tracking and does not request a new fix for a saved record. The points describe where your iPhone was when activity was observed. They do not locate an emitting device, and several points do not establish that one physical device was present at all of them.

When location access is already available, an Area Scan also asks iOS for the current approximate location. Apple’s Location Services may process that coordinate to provide a coarse neighbourhood or city label. Perimeter stores the resulting label with the Area Scan record; if a label cannot be resolved, it may store a city-scale coordinate rounded to two decimal places. It does not store a street address for this feature, and Bluetooth scan contents are not included in the location-label request.

Area Scans still work without location access, but no automatic location label is attached. Saved location information stays on the device unless you choose to include it in an export or share a report containing it.

Photos in a Place Check

Perimeter does not maintain a general photo library. Reference photos and comparison re-shoots are an editable local working set that exists only while a Check place remains open. Completing a Place Check creates immutable copies owned by that record. Closing out a place, or deleting it, removes the editable working set.

Photos taken or selected for a Check are stored inside Perimeter’s own storage. They are not uploaded and are not added to your iOS photo library. Completed copies follow the deletion lifecycle of the Place Check record they belong to.

Diagnostics in App Store V1 and pre-release builds

The App Store V1 build does not create or store a Perimeter diagnostics archive and does not include Report a Problem, Report this result, Extended Capture, Local Analytics, or a third-party telemetry SDK.

Internal and TestFlight pre-release builds may keep a privacy-minimised rolling diagnostics buffer so a tester can report a problem. That buffer stays local, is capped at 24 hours and 5 MiB, and is compiled out of the App Store V1 configuration. Standard diagnostics omit advertised device names and manufacturer payload prefixes.

In those pre-release builds, Extended Capture is a separate mode a tester starts explicitly. It may retain advertised local names, truncated manufacturer prefixes, and detailed rule evaluations locally within the same limits. Pre-release Local Analytics, when present, holds only on-device aggregate counts, contains no device or person identifiers, is not transmitted, and has its own Reset control.

Troubleshooting reports in pre-release builds

This section applies only to internal or TestFlight builds that include the pre-release reporting tools described above. Nothing is sent automatically. “Report this result” prepares a minimised report about one result; Settings → Diagnostics & Support → Report a Problem prepares one about a recent period. In both cases you review the report and choose whether to send it.

A prepared report may contain:

  • a report identifier, generation time, and the selected time window;
  • the description you type, and a human-readable summary;
  • app and build version, engine, classifier rule-set, evidence-corpus, calibration, and schema versions;
  • your iPhone hardware model class and iOS version;
  • scan lifecycle events, foreground/background transitions, and Bluetooth, notification, and location authorisation states — never location coordinates;
  • minimal radio structure needed to audit a classification: manufacturer identifier, advertised service UUIDs, service-data byte count and frame type, and RSSI;
  • classification family and confidence, accepted and evaluated rules, reason codes, and the radio-observation, product-identity, and coverage confidence values kept separately;
  • report-scoped aliases for the referenced observations, plus an inventory of what was included and what was omitted.

Before a report is created, local diagnostic subject keys are replaced with aliases scoped to that single report. Advertised local names, manufacturer payload bytes, internal test labels, free-form classifier prose, precise locations, Journey paths, and raw rotating Bluetooth bytes are removed. Reports do not include your photos, notes, saved records, or screenshots; if you choose to attach a screenshot yourself, you control what it shows.

How a report is sent. Perimeter prepares the report as a file and opens the system Mail composer addressed to testing@perimeterprivacy.com, with the report as an attachment. You must tap Send. If Mail is unavailable, Perimeter shows the destination address and offers the system share sheet so you can send it another way. Report contents are never placed in a URL or a mailto: query. Temporary copies are deleted after a successful hand-off or if you abandon the flow.

Reports are received by Perimeter at that address and held in restricted storage. They are used to diagnose and fix problems. They are not used for advertising or profiling, and they are not sold.

Crash reporting

Perimeter does not include a third-party crash-reporting service and does not send crash data to Perimeter-operated servers. During pre-release testing, crash and performance diagnostics may reach us through Apple’s TestFlight, and after release through App Store Connect, only when your iOS settings permit sharing diagnostics with developers. That data is collected and provided by Apple under Apple’s terms, and you can change it in iOS Settings → Privacy & Security → Analytics & Improvements.

Retention, deletion, and Clear History

Observation history and tracker evidence are subject to Perimeter’s in-app retention limits. Saved records remain on the device until you delete them or an applicable storage limit removes an older record. Deletion controls operate locally on your iPhone.

Clear History (Settings) permanently removes local detection history: observation episodes and their review state; tracker routes and waypoints; Area Scan records; completed Place Check records and their copied photos; open and closed Check places, drafts, signal comparisons and draft photos; room baselines, comparison history and photos; Familiar Place profiles, baselines, changes and review state; physical-tracker records and photos; Journey records; device dispositions; notification reconciliation and cooldown ledgers; and the local recovery snapshots described below. In a pre-release build that includes diagnostic history, Clear History removes that retained diagnostic history too.

Clear History deliberately preserves things that are settings rather than history: appearance, alert sensitivity and discretion, onboarding state, Known Places, the Journey preference, and other ordinary preferences. Local Analytics, when present in a pre-release build, is a separate store with its own Reset control and is not removed by Clear History.

Recovery snapshots. If a local archive cannot be read, Perimeter preserves the original file beside the archive before salvaging what it can, so that a storage fault does not silently destroy your records. These snapshots are local files only — they are never uploaded — and at most three are kept, oldest removed first. Clear History deletes them along with the archives themselves, so clearing history does not leave recoverable detection history behind. If the original file could not be preserved, Perimeter keeps the untouched original in place and reports a degraded state rather than overwriting it; Clear History still removes it.

Perimeter creates an export only when you ask it to. Once you save or share an exported report outside the app, its retention and use are controlled by the destination you selected rather than by Perimeter.

Website data

The public website has no account, email signup, or other personal-data form. It does not use advertising trackers, behavioural analytics, or third-party marketing scripts. Cloudflare hosts the site and may process ordinary operational information such as IP address, request time, requested URL, device or browser information, and security events in its service logs.

Previously collected availability-list emails

Until September 9, 2026, an earlier version of this website offered an email availability list. The current website no longer accepts new submissions. Addresses submitted through the earlier form may remain in a Cloudflare Workers KV namespace operated by Perimeter until the prior one-message commitment is completed, you request removal, or the list is discontinued.

A retained record may include the normalised email address, whether beta interest was selected, created and updated times, the call-to-action used, and submitted utm_source, utm_medium, or utm_campaign values. The list is not used for general marketing and is not sold or shared for advertising. No third-party email provider was configured at the time the form was removed.

Service providers and platform services

Cloudflare provides website hosting, request delivery, operational security, and storage for any retained entries from the prior availability list. It may maintain its own security and operational logs under its policies.

Apple provides iOS Location Services and the reverse-geocoding service used to produce an Area Scan’s coarse location label, and may process the approximate coordinate needed for that request under its own privacy terms. Perimeter does not include the Area Scan’s Bluetooth observations or nearby-device identifiers in that request. Apple also provides TestFlight and App Store distribution and the optional Apple crash and performance diagnostics described above.

If you share an exported report, a pre-release troubleshooting report, or a Journey check-in map link, the app you choose — Mail, Messages, Maps, or another destination — handles that content under its own terms.

Retention of website operational data

Operational hosting logs are retained according to Cloudflare account settings and applicable service policies. The current website does not create a visitor account or accept new availability-list entries. The prior list follows the retention and removal terms described above.

Children’s privacy

Perimeter and this website are not directed to children under 13. If you believe a child previously submitted an address to the availability list, contact us to request its removal.

Security

Reasonable technical and organisational safeguards are used to protect submitted information. No transmission or storage system can be guaranteed completely secure.

Changes to this policy

This policy may change as the app or website data practices change. Material changes will be reflected by a revised date on this page.

Contact

Privacy, deletion, and removal requests may be sent to hello@perimeterprivacy.com.

© Perimeter. Home · Support